ืขื“ื›ื•ืŸ OpenSSL 1.1.1j, wolfSSL 4.7.0 ื•-LibreSSL 3.2.4

ื–ืžื™ื ื” ืžื”ื“ื•ืจืช ืชื—ื–ื•ืงื” ืฉืœ ืกืคืจื™ื™ืช ื”ื”ืฆืคื ื” OpenSSL 1.1.1j, ืืฉืจ ืžืชืงื ืช ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2021-23841 ื”ื•ื ื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข NULL ื‘ืคื•ื ืงืฆื™ื” X509_issuer_and_serial_hash(), ืฉื™ื›ื•ืœื” ืœืงืจื•ืก ื™ื™ืฉื•ืžื™ื ืฉืงื•ืจืื™ื ืœืคื•ื ืงืฆื™ื” ื–ื• ืœื˜ืคืœ ื‘ืชืขื•ื“ื•ืช X509 ืขื ืขืจืš ืฉื’ื•ื™ ื‘ืฉื“ื” ื”ืžื ืคื™ืง.
  • CVE-2021-23840 ื”ื•ื ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื•ืช EVP_CipherUpdate, EVP_EncryptUpdate ื•-EVP_DecryptUpdate ืฉื™ื›ื•ืœื” ืœื’ืจื•ื ืœื”ื—ื–ืจืช ืขืจืš ืฉืœ 1, ื”ืžืฆื‘ื™ืข ืขืœ ืคืขื•ืœื” ืžื•ืฆืœื—ืช ื•ื”ื’ื“ืจืช ื”ื’ื•ื“ืœ ืœืขืจืš ืฉืœื™ืœื™, ืžื” ืฉืขืœื•ืœ ืœื’ืจื•ื ืœื™ื™ืฉื•ืžื™ื ืœืงืจื•ืก ืื• ืœืฉื‘ืฉ ื”ืชื ื”ื’ื•ืช ื ื•ืจืžืœื™ืช.
  • CVE-2021-23839 ื”ื•ื ืคื’ื ื‘ื™ื™ืฉื•ื ื”ื’ื ืช ื”ื—ื–ืจื” ืœืื—ื•ืจ ืœืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ SSLv2. ืžื•ืคื™ืข ืจืง ื‘ืกื ื™ืฃ ื”ื™ืฉืŸ 1.0.2.

ื›ืžื• ื›ืŸ ืคื•ืจืกืžื” ื”ืฉื—ืจื•ืจ ืฉืœ ื—ื‘ื™ืœืช LibreSSL 3.2.4, ื‘ืžืกื’ืจืชื” ืคืจื•ื™ืงื˜ OpenBSD ืžืคืชื— ืžื–ืœื’ ืฉืœ OpenSSL ืฉืžื˜ืจืชื• ืœืกืคืง ืจืžืช ืื‘ื˜ื—ื” ื’ื‘ื•ื”ื” ื™ื•ืชืจ. ื”ืžื”ื“ื•ืจื” ื‘ื•ืœื˜ืช ื‘ื”ื—ื–ืจื” ืœืงื•ื“ ืื™ืžื•ืช ื”ืชืขื•ื“ื” ื”ื™ืฉืŸ ืฉืฉื™ืžืฉ ื‘-LibreSSL 3.1.x ืขืงื‘ ืฉื‘ื™ืจื” ื‘ืืคืœื™ืงืฆื™ื•ืช ืžืกื•ื™ืžื•ืช ืขื bindings ื›ื“ื™ ืœืขืงื•ืฃ ื‘ืื’ื™ื ื‘ืงื•ื“ ื”ื™ืฉืŸ. ื‘ื™ืŸ ื”ื—ื™ื“ื•ืฉื™ื ื‘ื•ืœื˜ืช ื”ื•ืกืคืช ื”ื˜ืžืขื•ืช ืฉืœ ืจื›ื™ื‘ื™ ื”ื™ืฆื•ืืŸ ื•ื”-autochain ืœ-TLSv1.3.

ื‘ื ื•ืกืฃ, ื”ื™ื™ืชื” ืžื”ื“ื•ืจื” ื—ื“ืฉื” ืฉืœ ืกืคืจื™ื™ืช ื”ื”ืฆืคื ื” ื”ืงื•ืžืคืงื˜ื™ืช wolfSSL 4.7.0, ืžื•ืชืืžืช ืœืฉื™ืžื•ืฉ ื‘ืžื›ืฉื™ืจื™ื ืžืฉื•ื‘ืฆื™ื ืขื ืžืฉืื‘ื™ ืžืขื‘ื“ ื•ื–ื™ื›ืจื•ืŸ ืžื•ื’ื‘ืœื™ื, ื›ื’ื•ืŸ ืžื›ืฉื™ืจื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ื“ื‘ืจื™ื, ืžืขืจื›ื•ืช ื‘ื™ืช ื—ื›ื, ืžืขืจื›ื•ืช ืžื™ื“ืข ืœืจื›ื‘, ื ืชื‘ื™ื ื•ื˜ืœืคื•ื ื™ื ื ื™ื™ื“ื™ื. . ื”ืงื•ื“ ื›ืชื•ื‘ ื‘ืฉืคืช C ื•ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2.

ื”ื’ืจืกื” ื”ื—ื“ืฉื” ื›ื•ืœืœืช ืชืžื™ื›ื” ื‘-RFC 5705 (Keying Material Exporters for TLS) ื•-S/MIME (Secure/Multipurpose Internet Mail Extensions). ื ื•ืกืฃ ื“ื’ืœ "--enable-reproducible-build" ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ื‘ื ื™ื™ื” ื ื™ืชื ืช ืœืฉื—ื–ื•ืจ. ื”-API ืฉืœ SSL_get_verify_mode, X509_VERIFY_PARAM API ื•-X509_STORE_CTX ื ื•ืกืคื• ืœืฉื›ื‘ื” ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืชืื™ืžื•ืช ืขื OpenSSL. ืžื™ื•ืฉื ืžืืงืจื• WOLFSSL_PSK_IDENTITY_ALERT. ื ื•ืกืคื” ืคื•ื ืงืฆื™ื” ื—ื“ืฉื” _CTX_NoTicketTLSv12 ื›ื“ื™ ืœื”ืฉื‘ื™ืช ื›ืจื˜ื™ืกื™ ื”ืคืขืœื” ืฉืœ TLS 1.2, ืืš ืœืฉืžื•ืจ ืื•ืชื ืขื‘ื•ืจ TLS 1.3.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”